Getting Data In

timezone setting based on forwarder naming convention?

joesrepsolc
Communicator

I'm sure Splunk'rs have ran across this already, so here's my issue.

We have server naming conventions with "D" for DEV, "T" for TEST and "P" for PROD (in the same position of the server name). They reside in different data centers which are in different timezones. How do I set my props.conf to adjust the TZ value based on the naming convention of the host? The log sourcetypes are the same, going to the same index, but I need to adjust the TZ forward/back as these are in different data centers.

Is this setting made with REGEX in the inputs.conf of the app? Or is this done in the props.conf? Confused on exactly where/how to do this.

Thanks in advance!

0 Karma

woodcock
Esteemed Legend

You just do this in props.conf:

[host:.{number=character count preceding D, T, or P}D.*]
TZ=TZforDevHere
[host:.{number=character count preceding D, T, or P}T.*]
TZ=TZforTestHere
[host:.{number=character count preceding D, T, or P}P.*]
TZ=TZforProdHere
0 Karma
Get Updates on the Splunk Community!

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...